linux/Documentation
Matthew Garrett 000d388ed3 security: Add a static lockdown policy LSM
While existing LSMs can be extended to handle lockdown policy,
distributions generally want to be able to apply a straightforward
static policy. This patch adds a simple LSM that can be configured to
reject either integrity or all lockdown queries, and can be configured
at runtime (through securityfs), boot time (via a kernel parameter) or
build time (via a kconfig option). Based on initial code by David
Howells.

Signed-off-by: Matthew Garrett <mjg59@google.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Cc: David Howells <dhowells@redhat.com>
Signed-off-by: James Morris <jmorris@namei.org>
2019-08-19 21:54:15 -07:00
..
2019-06-21 10:18:16 -07:00
2019-05-14 19:52:48 -07:00
2019-05-07 18:02:51 -07:00
2019-05-16 11:57:16 -07:00
2018-10-25 06:50:48 -07:00
2018-03-26 12:13:21 -04:00
2018-12-18 16:13:04 +01:00
2019-05-08 17:13:35 -07:00
2019-04-08 14:13:43 +07:00
2019-02-22 08:50:17 -07:00
2019-05-21 10:11:19 +02:00
2019-05-24 09:09:32 -06:00
2019-05-09 08:40:55 -07:00
2019-03-10 12:47:57 -07:00
2018-05-08 09:16:41 -06:00